Junglewise Threat Intelligence

CVE-2026-49995: Tautulli stored XSS in newsletter cron field

CVE-2026-49995 · Severity: info · Published 2026-09-21

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli is a monitoring tool for Plex Media Server that includes a newsletter feature. An attacker with API access can inject malicious code into the newsletter cron field, which gets stored in the database. When an administrator later opens the newsletter configuration page, the malicious code executes in their browser, potentially allowing session hijacking or administrative actions to be performed without their knowledge.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the newsletter configuration HTML template where the cron field value is inserted into a JavaScript string without proper JSON encoding. An authenticated attacker with API key access can craft a cron value containing JavaScript payload, and any administrator viewing the newsletter config modal will trigger execution of the stored payload in their browser context.

Affected products

  • Tautulli Tautulli prior to 2.17.2

Timeline

  • 2026-09-21: disclosed
  • 2026-06-16: patched: Fixed in version 2.17.2

References

Related threats